Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is ransomware?

Ransomware is malicious activity that denies access to systems or data and demands payment or another concession. It can involve encryption, locking, deletion, theft, publication threats or service disruption - not necessarily one program encrypting files.

Describe what actually happened

Establish whether files changed, systems became unavailable, backups were damaged, data was collected or transferred, a demand was delivered and payment instructions were supplied. Malware, processes, notes, accounts, remote access, transfer records and communications can evidence different stages.

An outage with a note does not prove malware caused it, and encrypted files do not prove data theft. A note may be placed manually or make exaggerated claims.

Reconstruct the incident sequence

Keep initial access, privilege increase, discovery, collection, encryption, disruption, extortion and payment activity separate. Across many hosts, determine whether a central deployment caused the impact or distinct actions occurred on different systems.

Technical method, impact, infrastructure and offender identity are separate conclusions. The ransomware label should summarise supported behaviour, not substitute for it.

Key takeaway

Treat ransomware as a sequence of access, denial and extortion, proving encryption, theft, disruption and offender claims independently.

Reference: CIM-172Cyber Incidents & Offender Methods